RRAS in win2k server (all versions) supports NAT (network address translation). NAT in itself is a firewall, in the simplest sense. You can turn on port filters to reduce your security risk. I've setup several win2k servers running RRAS for clients, and they've never been hacked (knock on wood) in the 18 months they've been up. Make sure that before you expose a Windows server to the internet, that you lock it down. First and foremost, disable all accounts you don't need. Second change the default file permissions on all drives to be at least-
Administrators, system - full control
power users - modify (or server operators, since it's a server)
users - read
don't use the everyone group. also unbind file and print sharing, and client for microsoft networks from the interface connected to the internet.
search google for more info/help